CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85
CVEs mapped to this weakness (23,177)
page 918 of 1,159| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-16808 | 0.00 | — | 0.00 | Mar 7, 2019 | An issue was discovered in Dolibarr through 7.0.0. There is Stored XSS in expensereport/card.php in the expense reports plugin via the comments parameter, or a public or private note. | |||
| CVE-2018-20244 | 0.00 | — | 0.01 | Feb 27, 2019 | In Apache Airflow before 1.10.2, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. | |||
| CVE-2019-9142 | 0.00 | — | 0.00 | Feb 25, 2019 | An issue was discovered in b3log Symphony (aka Sym) before v3.4.7. XSS exists via the userIntro and userNickname fields to processor/SettingsProcessor.java. | |||
| CVE-2019-8331 | 0.00 | — | 0.02 | Feb 20, 2019 | In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute. | |||
| CVE-2019-8400 | 0.00 | — | 0.00 | Feb 17, 2019 | ORY Hydra before v1.0.0-rc.3+oryOS.9 has Reflected XSS via the oauth2/fallbacks/error error_hint parameter. | |||
| CVE-2018-20242 | — | 0.00 | — | 0.01 | Feb 11, 2019 | A carefully crafted URL could trigger an XSS vulnerability on Apache JSPWiki, from versions up to 2.10.5, which could lead to session hijacking. | ||
| CVE-2018-20757 | 0.00 | — | 0.00 | Feb 6, 2019 | MODX Revolution through v2.7.0-pl allows XSS via an extended user field such as Container name or Attribute name. | |||
| CVE-2018-20755 | 0.00 | — | 0.00 | Feb 6, 2019 | MODX Revolution through v2.7.0-pl allows XSS via the User Photo field. | |||
| CVE-2018-20756 | 0.00 | — | 0.00 | Feb 6, 2019 | MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Quick Edit action, or the viewing of manager logs. | |||
| CVE-2018-20758 | 0.00 | — | 0.00 | Feb 6, 2019 | MODX Revolution through v2.7.0-pl allows XSS via User Settings such as Description. | |||
| CVE-2019-1003014 | 0.00 | — | 0.00 | Feb 6, 2019 | An cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.4.1 and earlier in src/main/resources/lib/configfiles/configfiles.jelly that allows attackers with permission to define shared configuration files to execute arbitrary JavaScript when a user… | |||
| CVE-2019-1003013 | 0.00 | — | 0.00 | Feb 6, 2019 | An cross-site scripting vulnerability exists in Jenkins Blue Ocean Plugins 1.10.1 and earlier in blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/Export.java, blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/export/ExportConfig.java,… | |||
| CVE-2019-1003023 | 0.00 | — | 0.00 | Feb 6, 2019 | A cross-site scripting vulnerability exists in Jenkins Warnings Next Generation Plugin 1.0.1 and earlier in src/main/java/io/jenkins/plugins/analysis/core/model/DetailsTableModel.java, src/main/java/io/jenkins/plugins/analysis/core/model/SourceDetail.java,… | |||
| CVE-2018-16484 | — | 0.00 | — | 0.00 | Feb 1, 2019 | A XSS vulnerability was found in module m-server <1.4.2 that allows malicious Javascript code or HTML to be executed, due to the lack of escaping for special characters in folder names. | ||
| CVE-2018-16481 | — | 0.00 | — | 0.00 | Feb 1, 2019 | A XSS vulnerability was found in html-page <=2.1.1 that allows malicious Javascript code to be executed in the user's browser due to the absence of sanitization of the paths before rendering. | ||
| CVE-2018-16480 | — | 0.00 | — | 0.00 | Feb 1, 2019 | A XSS vulnerability was found in module public <0.1.4 that allows malicious Javascript code to run in the browser, due to the absence of sanitization of the file/folder names before rendering. | ||
| CVE-2019-7171 | 0.00 | — | 0.00 | Jan 29, 2019 | A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/blocks/blocks/edit/8. | |||
| CVE-2019-7170 | 0.00 | — | 0.00 | Jan 29, 2019 | A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/taxonomy/vocabularies. | |||
| CVE-2019-7173 | 0.00 | — | 0.00 | Jan 29, 2019 | A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/file-manager/attachments/edit/4. | |||
| CVE-2019-7168 | 0.00 | — | 0.00 | Jan 29, 2019 | A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Blog field to /admin/nodes/nodes/add/blog. |
- CVE-2018-16808Mar 7, 2019risk 0.00cvss —epss 0.00
An issue was discovered in Dolibarr through 7.0.0. There is Stored XSS in expensereport/card.php in the expense reports plugin via the comments parameter, or a public or private note.
- CVE-2018-20244Feb 27, 2019risk 0.00cvss —epss 0.01
In Apache Airflow before 1.10.2, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views.
- CVE-2019-9142Feb 25, 2019risk 0.00cvss —epss 0.00
An issue was discovered in b3log Symphony (aka Sym) before v3.4.7. XSS exists via the userIntro and userNickname fields to processor/SettingsProcessor.java.
- CVE-2019-8331Feb 20, 2019risk 0.00cvss —epss 0.02
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
- CVE-2019-8400Feb 17, 2019risk 0.00cvss —epss 0.00
ORY Hydra before v1.0.0-rc.3+oryOS.9 has Reflected XSS via the oauth2/fallbacks/error error_hint parameter.
- CVE-2018-20242Feb 11, 2019risk 0.00cvss —epss 0.01
A carefully crafted URL could trigger an XSS vulnerability on Apache JSPWiki, from versions up to 2.10.5, which could lead to session hijacking.
- CVE-2018-20757Feb 6, 2019risk 0.00cvss —epss 0.00
MODX Revolution through v2.7.0-pl allows XSS via an extended user field such as Container name or Attribute name.
- CVE-2018-20755Feb 6, 2019risk 0.00cvss —epss 0.00
MODX Revolution through v2.7.0-pl allows XSS via the User Photo field.
- CVE-2018-20756Feb 6, 2019risk 0.00cvss —epss 0.00
MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Quick Edit action, or the viewing of manager logs.
- CVE-2018-20758Feb 6, 2019risk 0.00cvss —epss 0.00
MODX Revolution through v2.7.0-pl allows XSS via User Settings such as Description.
- CVE-2019-1003014Feb 6, 2019risk 0.00cvss —epss 0.00
An cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.4.1 and earlier in src/main/resources/lib/configfiles/configfiles.jelly that allows attackers with permission to define shared configuration files to execute arbitrary JavaScript when a user…
- CVE-2019-1003013Feb 6, 2019risk 0.00cvss —epss 0.00
An cross-site scripting vulnerability exists in Jenkins Blue Ocean Plugins 1.10.1 and earlier in blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/Export.java, blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/export/ExportConfig.java,…
- CVE-2019-1003023Feb 6, 2019risk 0.00cvss —epss 0.00
A cross-site scripting vulnerability exists in Jenkins Warnings Next Generation Plugin 1.0.1 and earlier in src/main/java/io/jenkins/plugins/analysis/core/model/DetailsTableModel.java, src/main/java/io/jenkins/plugins/analysis/core/model/SourceDetail.java,…
- CVE-2018-16484Feb 1, 2019risk 0.00cvss —epss 0.00
A XSS vulnerability was found in module m-server <1.4.2 that allows malicious Javascript code or HTML to be executed, due to the lack of escaping for special characters in folder names.
- CVE-2018-16481Feb 1, 2019risk 0.00cvss —epss 0.00
A XSS vulnerability was found in html-page <=2.1.1 that allows malicious Javascript code to be executed in the user's browser due to the absence of sanitization of the paths before rendering.
- CVE-2018-16480Feb 1, 2019risk 0.00cvss —epss 0.00
A XSS vulnerability was found in module public <0.1.4 that allows malicious Javascript code to run in the browser, due to the absence of sanitization of the file/folder names before rendering.
- CVE-2019-7171Jan 29, 2019risk 0.00cvss —epss 0.00
A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/blocks/blocks/edit/8.
- CVE-2019-7170Jan 29, 2019risk 0.00cvss —epss 0.00
A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/taxonomy/vocabularies.
- CVE-2019-7173Jan 29, 2019risk 0.00cvss —epss 0.00
A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/file-manager/attachments/edit/4.
- CVE-2019-7168Jan 29, 2019risk 0.00cvss —epss 0.00
A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Blog field to /admin/nodes/nodes/add/blog.